# Does Mender Gateway support certificate chain validation with Intermediate CAs for mTLS?

**URL:** <https://hub.mender.io/t/does-mender-gateway-support-certificate-chain-validation-with-intermediate-cas-for-mtls/8185>\
**Category:** General Discussions\
**Tags:** gateway\
**Created:** [February 3, 2026, 7:11am UTC](https://hub.mender.io/t/does-mender-gateway-support-certificate-chain-validation-with-intermediate-cas-for-mtls/8185 "2026-02-03T07:11:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![marifante](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/marifante/32/2652_2.png) [@marifante](https://hub.mender.io/u/marifante)\
**Post date:** [February 3, 2026, 7:11am UTC](https://hub.mender.io/t/does-mender-gateway-support-certificate-chain-validation-with-intermediate-cas-for-mtls/8185/1 "2026-02-03T07:11:54Z")

</div>

Hi,

We are designing a device authorization model for our IoT fleet using mTLS with Mender Gateway (Enterprise). We want to implement a two-level CA hierarchy:

Root CA (stored in HSM, long-lived)  
└── Intermediate CA (couple of years validity)  
└── Device Certificates (signed by Intermediate CA)

The goal is to:

- Keep the Root CA secure and rarely used (only to sign Intermediate CAs)
- Use the Intermediate CA to sign device certificates
- Enable Intermediate CA rotation without reconfiguring Mender Gateway
- Allow recovery from Intermediate CA compromise without full PKI rebuild

**Our question:**

Does Mender Gateway support validating a certificate chain where the device certificate is signed by an Intermediate CA, which is itself signed by the Root CA?

Specifically:

1. If we configure MTLS\_CA\_CERTIFICATE with the Root CA, will Mender Gateway validate the full chain (Device cert → Intermediate CA → Root CA)?
2. Or do we need to provide a CA bundle (concatenated Root CA + Intermediate CA certificates)?
3. Is there any documentation on certificate chain validation for mTLS?

We reviewed the following documentation but couldn’t find explicit information about Intermediate CA support or certificate chain validation:

- [Mutual TLS authentication | Mender documentation](https://docs.mender.io/server-integration/mender-gateway/mutual-tls-authentication)
- [Certificates and keys | Mender documentation](https://docs.mender.io/server-installation/overview/certificates-and-keys)
- [Device Authentication | Mender documentation](https://docs.mender.io/overview/device-authentication)
- [Mender Server | Mender documentation](https://docs.mender.io/server-installation/production-installation-with-kubernetes/mender-server#mutual-tls)

Thanks in advance for any guidance.

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 4, 2026, 9:07pm UTC](https://hub.mender.io/t/does-mender-gateway-support-certificate-chain-validation-with-intermediate-cas-for-mtls/8185/2 "2026-02-04T21:07:03Z")

</div>

Hi @marifante ,

while the Mender Gateway is configured with the Root CA only, you can add the rest of the CA Chain in the device itself: this means chaining together the Intermediate CA and the Device cert in the `/data/mender/mender-cert.pem`; this way you should be able to get proper device authorization, and also ease the Intermediate CA rotation: you just have to create a regular Mender update to send the new Intermediate CA and client cert to the device.

---

<div class="post-metadata">

**Author:** ![marifante](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/marifante/32/2652_2.png) [@marifante](https://hub.mender.io/u/marifante)\
**Post date:** [February 5, 2026, 8:09am UTC](https://hub.mender.io/t/does-mender-gateway-support-certificate-chain-validation-with-intermediate-cas-for-mtls/8185/3 "2026-02-05T08:09:06Z")

</div>

> [@robgio](#):
>
> Mender Gateway is configured with the Root CA only, you can add the rest of the CA Chain in the device itself: this means chaining tog

Thanks Rob! That information is really helpful. We’ll try this setup 🙂
